PatchSiren

Infor CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Infor CVE published 2026-07-29

CVE-2025-60931

An Insecure Direct Object Reference (IDOR) vulnerability exists in Infor Global HR v11.24.10.01.33, allowing unauthorized attackers to view compensation information of other employees via crafted GET requests. This IDOR vulnerability can lead to potential unauthorized access to sensitive employee compensation information. Defenders should verify exposure, restrict access, and monitor for suspicious reques [truncated]